Login Fail Pad
Log failed logins so you can see a brute-force attempt without installing a WAF.
Login Fail Pad is a proposed WordPress plugin — Log failed logins so you can see a brute-force attempt without installing a WAF. It is not available for download yet — 0 of the 40 votes needed have been cast. Vote to move it forward, or join the waitlist to be emailed on release.
Updated
At a glance
- Platform
- WordPress
- Status
- Collecting votes
- Votes
- 0 of 40 (40 to go)
- Requirements
- WordPress 6.4+, PHP 8.1+
- Integrations
- wp-login.php
- Pricing
- Free core + Pro · Pro from $19/year
- Build time
- ~4 weeks after threshold
The problem
Failed wp-login posts only show up in host logs, after the fact, and security plugins wrap that log in a paid firewall.
Who this WordPress plugin is for
Admins who want a failure list in wp-admin.
Login Fail Pad is a proposed WordPress plugin for Admins who want a failure list in wp-admin..
Failed logins are listed with time, username tried, and IP hash. You can see volume. It does not lock IPs — pair with a host firewall if you need that.
Proposed plugin features
What this WordPress plugin would include in an initial release.
-
Failure list
Time, username attempted, IP hash.
-
Volume
Counts per day so a spike is obvious.
-
No lockout
The first release only logs.
Not in the first release
Kept out of scope on purpose, so the first version ships small and focused.
- Automatic lockouts
- Captcha
- A WAF
Concept screens
What happens after you vote
Every draft follows the same path from proposal to release.
-
1
Collecting votes You are here
The community decides whether this plugin gets built.
-
2
Threshold reached
Enough votes — the draft enters the build queue.
-
3
In development
Scope stays close to the published feature list.
-
4
Ready to download
Waitlisted voters are emailed first, with download details.
wp-login.php
WordPress 6.4+, PHP 8.1+
Free core + Pro · Pro from $19/year
A security suite, server logs, XML-RPC Gate
Frequently asked questions
Common questions about this WordPress plugin draft.
Does this block the attacker?
No. It shows the attempt. Lockouts stay with your host or a WAF.
Are IPs stored in the clear?
The list stores a hash, plus a truncated display you can turn off.
Is Login Fail Pad available to download yet?
No. Login Fail Pad is a proposed WordPress plugin, not a finished download. It has 0 of the 40 votes needed before development starts.
What does Login Fail Pad do?
Log failed logins so you can see a brute-force attempt without installing a WAF. It is a WordPress plugin proposal published on DraftPlugins, where the community votes on which drafts get built.
When will Login Fail Pad be released?
Estimated build time is ~4 weeks after threshold. Everyone on the waitlist is emailed as soon as it ships.
How much will Login Fail Pad cost?
Expected pricing: Free core + Pro · Pro from $19/year. Pricing for a draft is indicative and can change before release.
How do I get notified when Login Fail Pad is ready?
Vote on this page and join the waitlist with your email. We only email you about Login Fail Pad — release notes and access details.
What does Login Fail Pad require?
Planned requirements: WordPress 6.4+, PHP 8.1+.